Issue metadata
Sign in to add a comment
|
Stack-use-after-return in TDiagnostics::writeDebug |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5468244153204736 Fuzzer: libFuzzer_gpu_swiftshader_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Stack-use-after-return READ 8 Crash Address: 0x7f880cb77960 Crash State: TDiagnostics::writeDebug TParseContext::trace Trace Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=549950:549963 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5468244153204736 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Jun 16 2018
Automatically adding ccs based on OWNERS file / target commit history. If this is incorrect, please add ClusterFuzz-Wrong label.
,
Jun 16 2018
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/92f16ea7c0a121caf3f73a75c87f407b545647dc (Generate gpu workaround list from text files). If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
,
Jun 16 2018
,
Jun 16 2018
,
Jun 18 2018
Not enne's change per se. It changed the order of workarounds in the list, which means the interpretation of the "config" bits for the fuzzer changes over that CL, however the issue predates it.
,
Jun 19 2018
This code is only in Debug builds, so it's low severity.
,
Jun 26 2018
The following revision refers to this bug: https://swiftshader.googlesource.com/SwiftShader.git/+/659d89e94bf94240805b1d075017e43e8b388095 commit 659d89e94bf94240805b1d075017e43e8b388095 Author: Nicolas Capens <capn@google.com> Date: Tue Jun 26 19:29:19 2018 Support glCopyTexImage2D for float formats. Bug chromium:853424 Change-Id: I9b2de054baf6b042bcd04c5d023099a39ca20d2a Reviewed-on: https://swiftshader-review.googlesource.com/19569 Tested-by: Nicolas Capens <nicolascapens@google.com> Reviewed-by: Alexis Hétu <sugoi@google.com> [modify] https://crrev.com/659d89e94bf94240805b1d075017e43e8b388095/src/OpenGL/libGLESv2/libGLESv2.cpp [modify] https://crrev.com/659d89e94bf94240805b1d075017e43e8b388095/tests/unittests/unittests.cpp
,
Jul 5
The following revision refers to this bug: https://swiftshader.googlesource.com/SwiftShader.git/+/e1fa9ea70faa6931505bce64f5d97539c88712e9 commit e1fa9ea70faa6931505bce64f5d97539c88712e9 Author: Nicolas Capens <capn@google.com> Date: Thu Jul 05 17:13:23 2018 Reject copying from GL_RGB10_A2 to unsized formats. glCopyTexImage2D() with an framebuffer format of GL_RGB10_A2 and internalformat of GL_LUMINANCE_ALPHA was hitting the UNIMPLEMENTED() assert. The spec states that: If an effective internal format exists that has * the same component sizes as, * component sizes greater than or equal to, or * component sizes smaller than or equal to those of the source buffer's effective internal format (for all matching components in <internalformat>), that format is chosen for the new image array and this is the effective internal format of the new texel array. There is no unorm luminance+alpha format that has all components either greater or smaller, so this operation is invalid. Also see https://www.khronos.org/members/login/bugzilla/show_bug.cgi?id=9807#c56 Bug chromium:853424 Change-Id: Ia79a50bf7411a3f2aa87cf7f9bdbcbf971bdd7ce Reviewed-on: https://swiftshader-review.googlesource.com/19768 Tested-by: Nicolas Capens <nicolascapens@google.com> Reviewed-by: Alexis Hétu <sugoi@google.com> [modify] https://crrev.com/e1fa9ea70faa6931505bce64f5d97539c88712e9/src/OpenGL/libGLESv2/libGLESv2.cpp
,
Jul 6
ClusterFuzz has detected this issue as fixed in range 572608:573021. Detailed report: https://clusterfuzz.com/testcase?key=5468244153204736 Fuzzer: libFuzzer_gpu_swiftshader_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Stack-use-after-return READ 8 Crash Address: 0x7f880cb77960 Crash State: TDiagnostics::writeDebug TParseContext::trace Trace Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=549950:549963 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=572608:573021 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5468244153204736 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 6
ClusterFuzz testcase 5468244153204736 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jul 7
,
Aug 16
,
Oct 13
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Jun 16 2018Labels: Test-Predator-Auto-Components